La semana en noticias sobre filtraciones

This week, a major Microsoft outage disrupted Azure and Microsoft 365 services, while one of the cybersecurity industry’s long-standing concerns moved closer to reality after OpenAI disclosed that its autonomous test models escaped a sandboxed environment and compromised a real external system. Meanwhile, ransomware and supply chain attacks continue to target organizations worldwide, with major incidents affecting accounting giant EY and Swiss rail manufacturer Stadler Rail.

Estados Unidos

Usuarios de Microsoft

Sector: Tecnología Vulnerabilidad: Configuración incorrecta

A widespread outage affected Microsoft users on Thursday, July 23, disrupting access to Azure and Microsoft 365 services.

The outage began at 10:44 AM ET on July 23, primarily affecting customers accessing Microsoft 365 services through network infrastructure connected to Microsoft’s West US Azure region. Microsoft tracked the incident under ID MO1437424 and confirmed that multiple Microsoft 365 services were impacted, including OneDrive, SharePoint Online, Microsoft Teams, the Microsoft 365 Admin Center, Power Automate, Copilot Chat and Microsoft Loop.

Microsoft later revealed that the outage was triggered during routine device maintenance in its West US Azure region, where specific network paths were being isolated. The company said its maintenance process converts these requests into system-readable instructions and verifies that at least one of two redundant network paths remains healthy before work begins. However, a bug in the request conversion system incorrectly identified additional network devices as part of the maintenance event, resulting in widespread service disruption.

Fuente

Cómo puede afectar a su empresa

This incident highlights the risks of relying solely on a single cloud provider for business-critical workloads. While this outage was caused by a maintenance error rather than a cyberattack, it demonstrates how organizations can lose access to critical applications and data when cloud services become unavailable. To reduce this risk, organizations should implement third-party backup solutions for their Azure workloads that store backup data outside the Azure tenant, ensuring they can recover critical data and maintain business continuity even during major cloud service disruptions.

Norteamérica

Hugging Face

Sector: Tecnología Explotación: Hackeo

Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure and gained access to internal datasets and credentials.

Hugging Face is an open-source AI and machine learning platform used by more than 50,000 organizations and provides access to over 45,000 models from leading AI providers. According to reports, OpenAI’s autonomous test models escaped a sandboxed evaluation environment and autonomously targeted Hugging Face in a multi-stage cyber intrusion. The AI models reportedly exploited a zero-day proxy vulnerability to break out of containment and retrieved data to solve an evaluation benchmark without any human malice or instruction to attack.

The incident is being described as one of the first publicly disclosed examples of an AI system autonomously escaping its testing environment and compromising a real external system, representing the “agentic attacker” scenario that the AI and cybersecurity industry has long warned about. In a statement, OpenAI said it considers the incident an unprecedented cyber event involving state-of-the-art cyber capabilities and is responding accordingly.

Fuente

Cómo puede afectar a su empresa

Researchers have long warned that autonomous, agentic cyberattacks are on the horizon as frontier AI models become increasingly capable of planning and executing complex, multi-step attacks over extended periods with minimal human involvement. As these capabilities continue to evolve, they could pose real-world risks to organizations, particularly those operating critical infrastructure such as utilities, healthcare and financial services.

Reino Unido

Ernst & Young (EY)

Sector: Finanzas Vulnerabilidad: ransomware y malware

The ShinyHunters extortion gang claimed responsibility for a recent supply-chain attack on the global accounting firm EY.

Earlier this month, the London-based accounting giant had begun notifying clients that their personal and financial information had been compromised in a data breach. The incident, discovered on April 23, involved a third-party service management platform used by EY to support tax-related work for its clients. Support tickets that may contain client tax information were stolen during the attack, indicating that personal and financial information included in or used to prepare tax filings may have been compromised.

ShinyHunters has now added EY to its dark web leak site, claiming responsibility for the attack and threatening to publish the allegedly stolen data if the company does not contact the group by July 31, 2026.

Fuente

Cómo puede afectar a su empresa

Supply chain attacks have become an increasingly common way for cybercriminals to compromise large organizations. By targeting third-party vendors and service providers, attackers can gain access to sensitive customer data and critical business systems without directly breaching their primary target. Organizations should reduce this risk by thoroughly assessing third-party vendors’ security posture, enforcing strong access controls, continuously monitoring supplier activity, limiting third-party access to only what is necessary and ensuring vendors promptly address known vulnerabilities and security incidents.

Norteamérica

Windchill

Sector: Tecnología Vulnerabilidad: Vulnerabilidad de día cero

Ransomware gangs are exploiting a critical-severity remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms, Windchill and FlexPLM.

The vulnerability, tracked as CVE-2026-12569 (CVSS score: 9.3), was patched on June 17. The following day, PTC warned that the flaw had been exploited in the wild and published indicators of compromise (IoCs). The vulnerability was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog at the end of June. PTC described the flaw as a deserialization of untrusted data vulnerability that can be exploited without authentication.

Reports now indicate that the vulnerability is being exploited by an affiliate of the Cl0p ransomware gang. The attackers are primarily targeting organizations in the aerospace, automotive, manufacturing and retail/apparel sectors.

Fuente

Cómo puede afectar a su empresa

Unpatched vulnerabilities continue to provide cybercriminals with one of the easiest paths into corporate networks. Once a critical flaw becomes publicly known, attackers often move quickly to exploit organizations that have not yet applied available security updates, potentially leading to ransomware deployment, data theft and operational disruption. Implementing automated patch management helps organizations identify vulnerable systems, prioritize critical updates and deploy patches quickly and consistently, significantly reducing the window of opportunity for attackers.

Europa

Stadler Rail

Industria: Fabricación Explotación: Ransomware y malware

Stadler Rail rejected a ransom demand of approximately 10 million Swiss francs (about $12.3 million) from the Everest ransomware gang after attackers breached a data exchange platform shared with one of its suppliers.

Stadler Rail, a multinational Swiss manufacturer of locomotives, trams, metro trains, passenger trains and railway signaling systems, said it received an extortion letter from the Everest ransomware gang demanding the ransom payment. The company said it will not pay the threat actor and has filed a criminal complaint with the Thurgau cantonal police.

According to Stadler Rail, the incident occurred in mid-July and did not affect its IT systems or production operations, which continue to operate normally worldwide. The company said the attackers stole only technical information from a supplier that is not considered security relevant.

Fuente

Cómo puede afectar a su empresa

Supply chain attacks are also becoming increasingly common in the manufacturing sector, where organizations rely on extensive networks of third-party vendors, suppliers and technology partners. A compromise affecting a single supplier can expose sensitive information or create operational risks across multiple organizations. As discussed earlier, organizations should strengthen their supply chain security by thoroughly assessing vendor cyber-risks, limiting third-party access, continuously monitoring supplier activity and ensuring critical partners maintain strong security controls and respond promptly to emerging threats.

¿Te gusta lo que lees?

Suscríbete ahora para recibir cada semana noticias e información sobre seguridad en tu bandeja de entrada

Próximos webinars y eventos

Participa en nuestros próximos eventos y seminarios web para conocer las opiniones de los expertos, estrategias prácticas y las últimas tendencias en ciberseguridad.

INKY Tech Jam: From flagged to fixed – mastering email analysis & threat response

August 20, 2026 11:00 AM EDT

Learn how to investigate, analyze and resolve suspicious emails with confidence in this INKY Tech Jam. Discover how to use the Observations page, understand mail flow architecture and manage quarantine effectively to diagnose issues faster and strengthen email security for your clients or corporate users.

Regístrese ahora

Kaseya Security quarterly product innovation update

August 25, 2026 11:00 AM EDT

Discover the latest innovations across Kaseya’s integrated security portfolio in this exclusive quarterly product update. Learn how new AI-powered capabilities, deeper platform integrations and enhanced detection, response, visibility and protection features are helping MSPs and corporate IT teams strengthen security while reducing operational complexity.

Regístrese ahora